Italian Private Banking Giant Fideuram Falls Victim to AI Voice Scam
TREE NEWS reports: In February 2026, Paolo Molesini, former chairman of Italian private banking giant Fideuram, received a phone call from someone impersonating Carlo Messina, CEO of Intesa Sanpaolo Group. The voice on the line was convincing enough to trigger a series of transactions that ultimately resulted in at least €36 million being converted into cryptocurrency. The incident marks one of the largest known AI-assisted social engineering heists targeting a European financial institution.
How the Attack Unfolded
The attackers leveraged AI-powered voice cloning technology to mimic a trusted executive’s voice, a technique that has become increasingly accessible and inexpensive. Unlike traditional phishing emails, voice deepfakes exploit human psychology by adding real-time urgency and authority. The former chairman, reportedly acting on instructions he believed came from the CEO, authorized transfers that were subsequently funneled into crypto assets, making tracing and recovery exceptionally difficult.
Why Crypto Is the Exit of Choice
The choice of cryptocurrency as the final destination is telling. Unlike traditional bank wires, which can be frozen or reversed through correspondent banking networks, crypto transactions are irreversible and can be moved across borders within minutes. Attackers typically route funds through mixers, chain-hopping bridges, and privacy coins to obscure the trail. For European banks, this case underscores a painful reality: even robust AML/KYC frameworks at the fiat on-ramp are insufficient when the initial authorization comes from a legitimate insider who has been socially engineered.
Broader Implications for Financial Institutions
- AI-enabled fraud is scaling: Voice cloning tools now cost pennies per minute, democratizing high-fidelity impersonation for criminal groups.
- Insider authorization is the weakest link: Multi-signature and out-of-band verification protocols must extend beyond junior staff to executives and board members.
- Crypto’s role in post-theft laundering: Regulators may accelerate requirements for Travel Rule compliance and exchange-level transaction monitoring.
- Reputational and regulatory fallout: Italian and EU authorities are likely to scrutinize internal controls at Fideuram and its parent Intesa Sanpaolo.
Forward-Looking Perspective
This incident is unlikely to be isolated. As generative AI matures, the cost of orchestrating convincing deepfake attacks will continue to fall, while the potential payoff remains enormous. Financial institutions must treat voice and video authentication as a first-class security problem, not an afterthought. For the crypto industry, the case is a double-edged sword: it demonstrates the asset class’s utility for legitimate cross-border settlement, but also its attractiveness to sophisticated criminals. Expect heightened pressure on exchanges and custodians to implement real-time blockchain analytics, and expect European regulators to fold AI-fraud scenarios explicitly into DORA and MiCA implementation guidance.




